{"id":11652,"date":"2026-03-27T10:03:45","date_gmt":"2026-03-27T10:03:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/27\/isc-warns-of-high-severity-kea-dhcp-flaw-that-can-crash-services-remotely\/"},"modified":"2026-03-27T10:03:45","modified_gmt":"2026-03-27T10:03:45","slug":"isc-warns-of-high-severity-kea-dhcp-flaw-that-can-crash-services-remotely","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/27\/isc-warns-of-high-severity-kea-dhcp-flaw-that-can-crash-services-remotely\/","title":{"rendered":"ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely"},"content":{"rendered":"<p>    ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Internet Systems Consortium (ISC) has released a critical security advisory warning network administrators of a high-severity <a href=\"https:\/\/cybersecuritynews.com\/kea-dhcp-server-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability affecting the Kea DHCP server<\/a>.<\/p>\n<p>Tracked as CVE-2026-3608, this flaw allows unauthenticated remote attackers to trigger a stack overflow error.<\/p>\n<p>When successfully exploited, the vulnerability causes the receiving daemon to crash, resulting in a sudden and total loss of DHCP services across the network.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-kea-dhcp-vulnerability\">\n<strong>Kea DHCP<\/strong> <strong>Vulnerability<\/strong><br \/>\n<\/h2>\n<p>The vulnerability exists in how Kea daemons process incoming messages over specific listening channels.<\/p>\n<p>An attacker can exploit this weakness by sending a <a href=\"https:\/\/cybersecuritynews.com\/gafgyt-malware-attacks-docker-api-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">maliciously crafted message over any configured API socket<\/a> or High Availability (HA) listener.<\/p>\n<p>Because the incoming payload is not handled correctly by the software, <a href=\"https:\/\/cybersecuritynews.com\/cleanstack-a-dual-stack\/\" target=\"_blank\" rel=\"noreferrer noopener\">a stack overflow occurs<\/a>, forcing the service to terminate unexpectedly.<\/p>\n<p>This issue impacts multiple core components of the Kea architecture. The advisory explicitly notes that the\u00a0kea-ctrl-agent,\u00a0kea-dhcp-ddns,\u00a0kea-dhcp4, and\u00a0kea-dhcp6\u00a0daemons are all susceptible to this attack.<\/p>\n<p>Ali Norouzi from Keysight is credited with discovering and responsibly reporting the issue to the ISC. Carrying a CVSS v3.1 score of 7.5, CVE-2026-3608 represents a significant threat to network stability.<\/p>\n<p>The vulnerability requires <a href=\"https:\/\/cybersecuritynews.com\/microsoft-sql-server-zero-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero user interaction and no elevated privileges<\/a>, meaning any bad actor with network access to the API sockets can trigger the crash.<\/p>\n<p>The primary consequence of this exploit is a severe denial-of-service condition.<\/p>\n<p>When the Kea daemons exit, the network immediately loses its DHCP capabilities, which can <a href=\"https:\/\/cybersecuritynews.com\/massive-iptv-hosted-across-more-than-1000-domains\/\" target=\"_blank\" rel=\"noreferrer noopener\">disrupt IP address assignment<\/a>, break network connectivity for new devices, and severely impact enterprise operations.<\/p>\n<p>Fortunately, the ISC has stated that they are currently unaware of any active exploits in the wild.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-mitigations-and-workarounds\"><strong>Mitigations and Workarounds<\/strong><\/h2>\n<p>To permanently resolve this vulnerability, <a href=\"https:\/\/kb.isc.org\/docs\/cve-2026-3608\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">the ISC strongly advises organizations to immediately upgrade<\/a> their Kea deployments to the latest patched releases.<\/p>\n<p>Administrators running the 2.6 branch should update to Kea 2.6.5. In comparison, those on the 3.0 branch must update to Kea 3.0.3 to secure their environments against potential <a href=\"https:\/\/cybersecuritynews.com\/nvidia-merlin-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial-of-service attacks<\/a>.<\/p>\n<p>For network administrators who are unable to patch their systems right away, the ISC has provided an effective temporary workaround.<\/p>\n<p>Organizations can block the exploitation path by <a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-issued-1-billion-ssl-certificates\/\" target=\"_blank\" rel=\"noreferrer noopener\">securing their API sockets with Transport Layer Security (TLS)<\/a> and enforcing strict mutual authentication.<\/p>\n<p>By configuring the server to require a valid client certificate, administrators ensure that an attacker cannot establish the initial API connection required to deliver the malicious payload.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/isc-warns-kea-dhcp-flaw\/\">ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/isc-warns-kea-dhcp-flaw\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely The Internet Systems Consortium (ISC) has released a critical security advisory warning network administrators of a high-severity vulnerability affecting the Kea DHCP server. Tracked as CVE-2026-3608, this flaw allows unauthenticated remote attackers to trigger a stack overflow error. When successfully exploited, the vulnerability [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-11652","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11652"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11652"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11652\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11652"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11652"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11652"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}